Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

DEBIAN-CVE-2026-80926

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in oplock break notification smb2_oplock_break_noti() reads opinfo->conn without any lock and dereferenc...
Back to all
CVE

DEBIAN-CVE-2026-80926

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in oplock break notification smb2_oplock_break_noti() reads opinfo->conn without any lock and dereferenc...

In the Linux kernel, the following vulnerability has been resolved:  ksmbd: fix use-after-free in oplock break notification  smb2oplockbreaknoti() reads opinfo->conn without any lock and dereferences it after two allocations which may sleep.  When the durable handle owning the oplock is disconnected, sessionfdcheck() clears opinfo->conn and drops its conn reference under ci->mlock, and the last ksmbdconnput() frees the connection.  A break triggered by another connection that races with the teardown can then resurrect the freed connection: ksmbdconnget() is a plain atomicinc, and the queued break work later dereferences the stale conn via ksmbdconnwrite(), a use-after-free reachable by any authenticated client holding a durable batch oplock.  Thread the caller's inode into the notification path instead of taking a new reference on it.  Every caller of oplockbreak() already holds a live ksmbdfile (or an explicit ksmbdinodelookuplock() reference, in the parent lease break paths) on the inode that owns the break target's oplock list, so ci cannot be freed during the call, and its lock can be taken without dereferencing opinfo->ofp, which a concurrent close may free.  Select and pin the connection under ci->mlock, the same lock sessionfdcheck() and ksmbdreopendurable_fd() use to update opinfo->conn, so a concurrent detach either loses the race to the clear or keeps the connection alive until the notification work releases it.  Transfer the reference to the work item and release it on allocation failures.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
-
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://security-tracker.debian.org/tracker/CVE-2026-80926

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0%
EPSS Percentile
0%
Introduced Version
0
Fix Available
6.12.111-1,7.2.6-1,6.12.111-1~deb12u1

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading